Documentation9 min read

Ransomware Defense for SMBs: Layers, Backups & Incident Response

Ransomware is the #1 cause of SMB downtime. Learn the layered defenses — EDR, immutable backups, network segmentation, and a tested IR plan — that keep your business running when attackers strike.

Published August 1, 2026Updated August 25, 2026
RansomwareEDRBackupIncident ResponseCybersecuritySMBSentinelOne

Why ransomware hits SMBs hardest

Ransomware operators have shifted from targeting large enterprises to SMBs — smaller organizations with fewer defenses, less IT staff, and the same willingness to pay to get their data back. The average SMB ransom demand in 2025 exceeded $200,000. More damaging: the average downtime was 21 days.

The good news is that ransomware is preventable with the right layered stack. No single tool stops it — but the combination below does.

RANSOMWARE DEFENSE — LAYERED ARCHITECTURE LAYER 1 — PERIMETER Next-Gen Firewall (NGFW) DNS Filtering (Umbrella) Email Gateway / Defender 365 Web Proxy / CASB LAYER 2 — ENDPOINT EDR / XDR (SentinelOne) Patch Management (RMM) Application Allowlisting MFA Everywhere LAYER 3 — DATA PROTECTION Immutable Backup (3-2-1) Air-Gapped Offsite Copy Encryption at Rest & Transit VLAN Segmentation LAYER 4 — DETECTION & RESPONSE SIEM / SOC (Adlumin) 24/7 Threat Monitoring Incident Response Plan Tabletop Exercises Figure 1 — Four-layer ransomware defense. Each layer independently reduces risk; together they stop the kill chain.

Figure 1 — Four-layer ransomware defense architecture. Each layer independently reduces risk; together they stop the full kill chain.

The ransomware kill chain — and where to break it

Kill Chain StageAttacker ActionDefense That Breaks It
Initial AccessPhishing email, RDP brute-force, unpatched CVEEmail gateway, MFA, patch management
ExecutionMalicious macro, PowerShell dropperEDR behavioral detection, application allowlisting
PersistenceRegistry keys, scheduled tasks, new admin accountsEDR rollback, privileged access management
Lateral MovementPass-the-hash, SMB spread across flat networkVLAN segmentation, least-privilege accounts
ExfiltrationData staged and sent to C2 before encryptionDLP, DNS filtering, CASB
EncryptionFiles encrypted, ransom note droppedEDR autonomous rollback (SentinelOne Storyline)
RecoveryAttacker demands paymentImmutable backup restore — no payment needed

Immutable backups: your last line of defense

An immutable backup cannot be encrypted, deleted, or modified — even by a ransomware operator who has compromised your admin credentials. The 3-2-1 rule is the minimum:

  • 3 copies of data
  • 2 different media types (e.g., local NAS + cloud)
  • 1 copy offsite and air-gapped

IDENETY uses Datto for immutable, air-gapped backup with tested restore SLAs. We test restores quarterly — not just assume they work.

Backup without a tested restore is not a backup. Most SMBs discover their backup was broken during the ransomware incident. IDENETY schedules quarterly restore tests and documents the results as part of the COMPLETE plan.

Incident response: the 72-hour playbook

When ransomware fires, the first 72 hours determine whether you pay or recover. Your IR plan must answer these questions before an incident:

  • Who declares the incident and who is the incident commander?
  • Which systems get isolated first (domain controllers, file servers)?
  • What is the RTO/RPO for each critical system?
  • Who contacts cyber insurance, legal counsel, and law enforcement?
  • What is the communication plan for customers and staff?

IDENETY ransomware protection stack

  • SentinelOne EDR with autonomous rollback — included in COMPLETE plan.
  • Adlumin SIEM with 24/7 SOC monitoring.
  • Datto immutable backup with quarterly restore testing.
  • VLAN segmentation to contain lateral movement.
  • Tabletop IR exercises available as a professional service.

Contact our engineers to assess your current ransomware exposure and build a remediation roadmap.

Ransomware defense and managed cybersecurity in San Antonio, Austin, Houston, and Texas. IDENETY is a San Antonio-based managed security services provider (MSSP) protecting SMBs and enterprise organizations across Texas and 34+ states. Our COMPLETE plan includes SentinelOne EDR, Adlumin SIEM with 24/7 SOC, and immutable Datto backups. Call (726) 224-2222 or request a ransomware assessment.
About the Author